Skip to Content
OPINION

A view from Brussels: The suspension of disbelief

The EU's latest simplification effort extends GDPR record-keeping exemptions to more companies, though many organizations may see little practical change to their compliance obligations.

Published
Subscribe to IAPP Newsletters

Contributors:

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

Conceptualized during Greco-Roman times, the "suspension of disbelief" is a theory used in theatrical arts. It postulates that the audience tricks its mind to believe what is presented on stage, against logic or rational thinking, just because leaning into believing is the whole point. 

Some suspension of disbelief would be helpful as the EU simplification journey runs its course. Brussels has been debating digital reform for months, alongside reform of defense, agriculture, taxation, etc. And so, the first signal of simplification for the IAPP community came from the European Commission's Internal Market, Industry, Entrepreneurship and SMEs Directorate-General.

Proposed by the European Commission in May 2025, the Omnibus IV package will enter into force over the summer. Its primary objective is not privacy or digital reform, but rather to reduce regulatory burden by extending certain small and medium enterprise relief measures to a newly created category of companies, "small mid-cap" enterprises.

SMCs are companies with fewer than 1,000 employees and either annual turnover of up to 200 million euros or an annual balance-sheet total of up to 172 million euros — thresholds the European Parliament and Council increased from the Commission's original proposal.

For privacy professionals, Omnibus IV addresses one thing: Records of processing activities obligations under the EU General Data Protection Regulation.

The new law extends the GDPR's Article 30 derogation beyond SMEs to SMCs. In practice, organizations with fewer than 1,000 employees may no longer need to maintain a ROPA, provided their processing activities are not likely to result in a high risk to individuals' rights and freedoms.

One can genuinely debate whether, all things considered, addressing ROPAs was in fact the most impactful area to, quoting the Commission, "boost the competitiveness of EU companies." There is no point in relitigating the past, but we can certainly question what it does for the future.

The answer is underwhelming: Barely anything.

The first catch is that high-risk remains a limiting factor, rightfully so one would argue. Where a data protection impact assessment identifies processing that is likely to result in a high risk under Article 35 GDPR, the documentation obligation remains. 

The second catch concerns controllers and processors subject to data protection officer obligations. In this case, ROPAs remain necessary unless the relevant processing is merely ancillary to their core business and unlikely to present high risk. Public authorities, meanwhile, remain fully subject to the record-keeping requirement. 

The result is a halfway attempt at simplification. Organizations must still determine whether processing is high risk. They must still conduct DPIAs where required. Many must still appoint DPOs. And many will still decide to maintain records for at least part of their processing activities because it is an essential documentation tool for visibility, traceability and accountability.

Will SMCs that can benefit from this new exemption stop doing ROPAs? Some would be legally entitled to do so but the operational tradeoffs may not be worth it. 

This article originally appeared in the Europe Data Protection Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

Tags:

Law and regulationGDPRPrivacy

Related Stories